1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Tech Support Scammers Get Serious With Screen Lockers

Discussion in 'General Malware And Security' started by starbuck, May 17, 2016.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    b84105da5b14de58bb540a1105e4693a.png

    Tech support scammers are well aware of what is going on in the malware scene and often rip off ideas and concepts from other criminals.
    We see this today with for example bogus browser locks and fake AV alerts which are mostly an annoyance and can somewhat easily be disabled.

    But things have been changing with more serious malware-like techniques to force people into calling rogue tech support call centres.
    We previously saw a case of fake Blue Screen Of Death (BSOD) actually locking up people’s desktops and now there is a growing demand for such ‘products’.
    Below is a Facebook post advertising a locker specifically designed for tech support scams.
    It tricks users into thinking their Windows license has expired and blocks them from using their computer.

    3acd92fdac85695f24d893174da5dbc5.png

    To be clear, this is not a fake browser pop up that can easily be terminated by killing the application or restarting the PC. No, this is essentially a piece of malware that starts automatically, and typical Alt+F4 or Windows key tricks will not get rid of it.

    There is an entire ecosystem to distribute these tech support lockers, which includes bundling them into affiliate (Pay Per Install) applications.
    What you thought was a PC optimizer or Flash Player update turns out to be a bunch of useless toolbars and, in some cases, one of these lockers.
    Another reason yet, if there weren’t enough already to stay away from adware supported programs.

    A security researcher known as @TheWack0lian shared an interesting sample with us which truly resembles a genuine Microsoft program.
    It installs without any particular incident and waits for the user to restart their computer.
    When that happens, the program activates to take over the desktop and display what looks like Windows updates being installed:

    a678e3c394ef5814a0a4bb74666bb391.png

    This is a fake Windows update but the average user will probably not see the difference.
    More troubling is the next screen that comes up and effectively disables the computer because of an expired license key.
    The message looks legitimate with the license key and computer name being retrieved from the victim’s actual computer.

    3708c091c9285a51d1be2321a84358d3.png

    The only recourse it seems is to call the toll-free number for assistance.
    As you can imagine, these fake Windows programs are great leads for tech support call centres waiting to collect the credit card numbers of unsuspecting users.

    We called the number (1-844-872-8686) provided on the locked screen and after much back and forth, the technician revealed a hidden functionality to this locker.
    There is a built-in installer for TeamViewer which can be launched by a combination of the Ctrl+Shift+T keys:

    2ff68805d9e404d53e289bead4e48c21.png

    However, the rogue ‘Microsoft technician’ would not proceed any further until we paid the $250 fee to unlock the computer, which we weren’t going to.

    @TheWack0lian discovered a keyboard combo to disable the locker by holding Ctrl+Shift and press the S key.
    Alternatively, if you know someone facing this issue, you may be able to recover their computer by entering one of the hardcoded values for the ‘product key’: “h7c9-7c67-jb” or “g6r-qrp6-h2” or “yt-mq-6w”.
    Note that these may only work for this particular instance and not all versions of those lockers.

    155a6bd73e3d448fb667cd6f6988bde1.png

    Needless to say this is a worrying trend because in comparison to fake (but mostly harmless) browser alerts, these Windows lockers are a real pain to get rid of and until you do so, your computer is completely unusable.
    Just in the past few days we have noticed more and more users complaining about these new lockers.

    This increased sophistication means that people can no simply rely on common sense or avoid the typical cold calls from ‘Microsoft’.
    Now they need to also have their machines protected from these attacks because scammers have already started manufacturing malware tailored for what is essentially plain and simple extortion over the phone.

    Malwarebytes Anti-Malware detects this tech support locker as Rogue.TechSupportScam.



    Source:
    https://blog.malwarebytes.org/cyber...ort-scammers-get-serious-with-screen-lockers/
     
    Vger likes this.
  2. allheart55 (Cindy E)

    allheart55 (Cindy E) Administrator Administrator

    Joined:
    Jun 11, 2009
    Messages:
    10,620
    Location:
    Pennsylvania
    Operating System:
    Windows 10
    Computer Brand or Motherboard:
    ASUS M4A77TD AM3 AMD 770 ATX AMD
    CPU:
    AMD Phenom II X6 1090T-Thuban 3.2GHz
    Memory:
    Crucial-DDR3 SDRAM 1333-8GB
    Hard Drive:
    WD Caviar Black SE HDD 640 GB - WD Caviar Black SE HDD 500 GB
    Graphics Card:
    Sapphire Radeon HD-7870 2GB
    Power Supply:
    CORSAIR CMPSU-750W
    Wow! This is one of the best that I have seen yet.
    Thanks, Pete.
     
  3. Kenny94

    Kenny94 Registered Members

    Joined:
    Jan 21, 2016
    Messages:
    419
    Location:
    SC
    Operating System:
    OS X
    Computer Brand or Motherboard:
    iPad Air, HP Chromebook and Compaq laptop with xp
    This one is very clever! I mean nothing happens until you restart your system. You're having your morning coffee . Your thinking it's a Windows update that went bad. Then the more you read it, you're realizing something isn't totally right. The "knee-jerk reaction" kicks in, to make the call. The bad guys are asking for credit card numbers. By the time you wake up, you're 250.00 short. Yeah! Please,,,,don't fall for this one folks!
     
    Last edited: May 17, 2016

Share This Page